CVE-2025-23166 | Node.js Async Cryptographic Operation SignTraits::DeriveBits denial of service (Nessus ID 236766 / WID-SEC-2025-1569)
A vulnerability described as problematic has been identified in Node.js. The affected element is the function SignTraits::DeriveBits of the component Async Cryptographic Operation Handler. Such manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2025-23166. The attack can only be initiated within the local network. No exploit exists.
Upgrading the affected component is recommended.